PT-2026-24148 · Fmdns+1 · Fmdns+1

Rusi-Sec

·

Published

2026-03-09

·

Updated

2026-03-13

·

CVE-2026-30918

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions facileManager versions prior to 6.0.4
Description facileManager is a modular suite of web apps designed for system administrators. A reflected cross-site scripting (XSS) issue exists when the application processes data from an untrusted source and incorporates it into HTTP responses, potentially leading to security compromises. An attacker can inject malicious JavaScript code into a URL by including a script within a parameter. This vulnerability is present in the fmDNS module, specifically affecting the log search query parameter.
Recommendations Update to version 6.0.4 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-30918
GHSA-284F-MFF7-744X

Affected Products

File Manager
Fmdns